CVE-2020-8468 is a critical content validation escape vulnerability affecting Trend Micro Apex One (2019), OfficeScan XG, and Worry-Free Business Security (9.0, 9.5, 10.0) agents. This flaw allows an authenticated attacker to manipulate agent client components, leading to high impact on confidentiality, integrity, and availability. With a CVSS score of 8.8 (HIGH), it is easily exploitable over the network with low attack complexity. Notably, this vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog, despite no public exploit code being available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:* | ||
xgCPE matchmatch criteria | cpe:2.3:a:trendmicro:officescan:xg:-:*:*:*:*:*:* | ||
xgCPE matchmatch criteria | cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:trendmicro:worry-free_business_security:9.0:sp3:*:*:*:*:*:* | ||
9.5CPE matchmatch criteria | cpe:2.3:a:trendmicro:worry-free_business_security:9.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.